Red Hat Product Errata RHSA-2026:36199 - Security Advisory Issued: 2026-07-07 Updated: 2026-07-07 RHSA-2026:36199 - Security Advisory Overview Updated Packages Synopsis Important: buildah security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for buildah is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The buildah package provides a tool for facilitating building OCI container images. Among other things, buildah enables you to: Create a working container, either from scratch or using an image as a starting point; Create an image, either from a working container or using the instructions in a Dockerfile; Build both Docker and OCI images. Security Fix(es): golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate (CVE-2026-39835) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters (CVE-2026-39829) golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses (CVE-2026-39830) golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions (CVE-2026-39832) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480680 - CVE-2026-39835 golang.org/x/crypto/ssh: golang: golang.org/x/crypto/ssh: Denial of Service via crafted SSH certificate BZ - 2480681 - CVE-2026-39829 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via crafted public key with excessive parameters BZ - 2480684 - CVE-2026-39830 golang.org/x/crypto/ssh: golang.org/x/crypto/ssh: Denial of Service via resource leak from unsolicited SSH responses BZ - 2480685 - CVE-2026-39832 golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: Security bypass due to improper handling of key restrictions CVEs CVE-2026-39829 CVE-2026-39830 CVE-2026-39832 CVE-2026-39835 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 x86_64 buildah-1.43.1-3.el10_2.x86_64.rpm SHA-256: 07ee29246c36db90fd43f465ba78d8dad1e6e825778c83c30a0a0fe312ef0e85 buildah-debuginfo-1.43.1-3.el10_2.x86_64.rpm SHA-256: 0bd48cc55f080d2b63247ea653f605bf81e2e1b0c07a9eebdcc1b79113806d95 buildah-debugsource-1.43.1-3.el10_2.x86_64.rpm SHA-256: c3d7d8ea2fc98ee7610e01a6ef989f48d609b239dde19497cca8db5ad9fce815 buildah-tests-1.43.1-3.el10_2.x86_64.rpm SHA-256: 27bb52107ca1567a278550008d1ab239c6d6abe9371844f13bc061d07f250b10 buildah-tests-debuginfo-1.43.1-3.el10_2.x86_64.rpm SHA-256: 60369e8b4ed1bd3ef41e1b51a8a23de7bdf0bf9286b5d475725b07a904925f09 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 x86_64 buildah-1.43.1-3.el10_2.x86_64.rpm SHA-256: 07ee29246c36db90fd43f465ba78d8dad1e6e825778c83c30a0a0fe312ef0e85 buildah-debuginfo-1.43.1-3.el10_2.x86_64.rpm SHA-256: 0bd48cc55f080d2b63247ea653f605bf81e2e1b0c07a9eebdcc1b79113806d95 buildah-debugsource-1.43.1-3.el10_2.x86_64.rpm SHA-256: c3d7d8ea2fc98ee7610e01a6ef989f48d609b239dde19497cca8db5ad9fce815 buildah-tests-1.43.1-3.el10_2.x86_64.rpm SHA-256: 27bb52107ca1567a278550008d1ab239c6d6abe9371844f13bc061d07f250b10 buildah-tests-debuginfo-1.43.1-3.el10_2.x86_64.rpm SHA-256: 60369e8b4ed1bd3ef41e1b51a8a23de7bdf0bf9286b5d475725b07a904925f09 Red Hat Enterprise Linux for IBM z Systems 10 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 s390x buildah-1.43.1-3.el10_2.s390x.rpm SHA-256: 644069716b2e4ae4cdc245d0ce6b74a288a3b5fed65208954c2c708d585911b2 buildah-debuginfo-1.43.1-3.el10_2.s390x.rpm SHA-256: 0bf7c5636ad78e1ea92181c8e72f7233e6c9a25a0098eefe4e4872d4046b733f buildah-debugsource-1.43.1-3.el10_2.s390x.rpm SHA-256: 3ed2b5eba3064e7a90f755f0e87c23ea793502ceb008322f42be7b344096546d buildah-tests-1.43.1-3.el10_2.s390x.rpm SHA-256: c3a86c0b83945c0422871924d24e554e45f8156e3307bf76c459a71e633aaaab buildah-tests-debuginfo-1.43.1-3.el10_2.s390x.rpm SHA-256: 2b390e8a0b79d960a8d26e9fb47b9cc0033eeaf2cf0e9e4b9697380bf6226be8 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 s390x buildah-1.43.1-3.el10_2.s390x.rpm SHA-256: 644069716b2e4ae4cdc245d0ce6b74a288a3b5fed65208954c2c708d585911b2 buildah-debuginfo-1.43.1-3.el10_2.s390x.rpm SHA-256: 0bf7c5636ad78e1ea92181c8e72f7233e6c9a25a0098eefe4e4872d4046b733f buildah-debugsource-1.43.1-3.el10_2.s390x.rpm SHA-256: 3ed2b5eba3064e7a90f755f0e87c23ea793502ceb008322f42be7b344096546d buildah-tests-1.43.1-3.el10_2.s390x.rpm SHA-256: c3a86c0b83945c0422871924d24e554e45f8156e3307bf76c459a71e633aaaab buildah-tests-debuginfo-1.43.1-3.el10_2.s390x.rpm SHA-256: 2b390e8a0b79d960a8d26e9fb47b9cc0033eeaf2cf0e9e4b9697380bf6226be8 Red Hat Enterprise Linux for Power, little endian 10 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 ppc64le buildah-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 13b38c2af40bf79e47bfd52d3126b718c2e55fa55270131a3b568f57d30fff3f buildah-debuginfo-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 60dfd4a1fcb614ddb864319f30bdc4948c847370f2ac9390d758cdc84cc6a6de buildah-debugsource-1.43.1-3.el10_2.ppc64le.rpm SHA-256: d8690da0814702490d24098a792aa417e9e821501e16cf514c896931a7716b4b buildah-tests-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 321fecaa535848b3d984f9c595621e4075a48b074f7fff3579d839d7e95f4c2d buildah-tests-debuginfo-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 14f890532aa23799b8c54aa4233ec1de149e6d9067e8b2d6d57acc29ca1e826c Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 ppc64le buildah-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 13b38c2af40bf79e47bfd52d3126b718c2e55fa55270131a3b568f57d30fff3f buildah-debuginfo-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 60dfd4a1fcb614ddb864319f30bdc4948c847370f2ac9390d758cdc84cc6a6de buildah-debugsource-1.43.1-3.el10_2.ppc64le.rpm SHA-256: d8690da0814702490d24098a792aa417e9e821501e16cf514c896931a7716b4b buildah-tests-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 321fecaa535848b3d984f9c595621e4075a48b074f7fff3579d839d7e95f4c2d buildah-tests-debuginfo-1.43.1-3.el10_2.ppc64le.rpm SHA-256: 14f890532aa23799b8c54aa4233ec1de149e6d9067e8b2d6d57acc29ca1e826c Red Hat Enterprise Linux for ARM 64 10 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 aarch64 buildah-1.43.1-3.el10_2.aarch64.rpm SHA-256: cafb8e5239f396d1e37ee90a5da4c0a4e36292b124b5febd4d72d7c44756f1be buildah-debuginfo-1.43.1-3.el10_2.aarch64.rpm SHA-256: e80abbd594305ef58c7a9a7b681fd5b66f65501ae9603c4a07d3390e87ad9ced buildah-debugsource-1.43.1-3.el10_2.aarch64.rpm SHA-256: ba689da5d4ee15360ac8ad99f4a9e7ae59a038b2e84d79c0b25f13bdbb1ad030 buildah-tests-1.43.1-3.el10_2.aarch64.rpm SHA-256: 644b7fe010255fe345bdb6a98a7711df8da36cc575698d989b1ab0ae2ab87904 buildah-tests-debuginfo-1.43.1-3.el10_2.aarch64.rpm SHA-256: d8dea03d7640128bc466184d77012aad917b93da19c5a50ed8960be3ed252546 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM buildah-1.43.1-3.el10_2.src.rpm SHA-256: 4cd0707a60158b93b71ba365e16cbcc9f878cbe0ea3cb9ac17fde0f2f04d06e0 aarch64 buildah-1.43.1-3.el10_2.aarch64.rpm SHA-256: cafb8e5239f396d1e37ee90a5da4c0a4e36292b124b5febd4d72d7c44756f1be buildah-debuginfo-1.43.1-3.el10_2.aarch64.rpm SHA-256: e80abbd594305ef58c7a9a7b681fd5b66f65501ae9603c4a07d3390e87ad9ced buildah-debugsource-1.43.1-3.el10_2.aarch64.rpm SHA-256: ba689da5d4ee15360ac8ad99f4a9e7ae59a038b2e84d79c0b25f13bdbb1ad030 buildah-tests-1.43.1-3.el10_2.aarch64.rpm SHA-256: 644b7fe010255fe345bdb6a98a7711df8da36cc575698d989b1ab0ae2ab87904 buildah-tests-debuginfo-1.43.1-3.el10_2.aarch64.rpm SHA-256: d
This security update addresses multiple vulnerabilities in the golang.org/x/crypto/ssh library used by Buildah, including a critical (CVSS 9.1) denial-of-service via resource leak from unsolicited SSH responses, a high-severity (CVSS 7.5) DoS via crafted public keys, and other issues. The affected versions are golang crypto library versions prior to 0.52.0, and the fix requires updating the underlying library to version 0.52.0.